mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-09-16 19:40:43 +02:00
* security: reload JWT signing keys on SIGHUP Signing keys were read once in the server constructors and never refreshed. After a key rotation (Secret update, divergent reads) the in-memory key stayed stale and every request kept failing "wrong jwt" until the affected process was restarted. Add Guard.UpdateSigningKeys and call it from the master, volume and filer reload paths and the s3 reload hook, next to the existing whitelist refresh. Make the global chunk-read JWT cache reloadable via an atomic swap, and register the master's Reload with grace.OnReload -- it was never wired, so the master ignored SIGHUP entirely. Mirror the same refresh in the Rust volume server's SIGHUP handler. * security: swap signing keys behind an atomic pointer Addresses review feedback on the in-place key swap: SigningKey is a []byte, so reassigning the Guard fields while a request handler reads them is a data race that can tear the multi-word slice header and read out of bounds. Hold the four signing-key fields in an immutable signingConfig snapshot behind atomic.Pointer; UpdateSigningKeys swaps the whole pointer, so a reader sees either the old keys or the new ones. Reads go through new SigningKey/ExpiresAfterSec/ReadSigningKey/ReadExpiresAfterSec accessors. The Rust guard is already safe: every read and the SIGHUP write go through the shared RwLock<Guard>. * security: fold whitelist + auth state into the atomic snapshot Review follow-up. UpdateSigningKeys still wrote isWriteActive while the request path read it (and the whitelist maps) unsynchronized, so a SIGHUP under load could expose an inconsistent mix of activation bits and whitelist contents. Move all hot-reloadable Guard state -- keys, expirations, whitelist, and the activation flags -- into a single immutable guardState swapped behind one atomic.Pointer. The Update* methods take a small mutex to serialize the read-modify-write; readers stay lock-free. The concurrency test now also rotates the whitelist and probes IsWhiteListed under -race. Also read each signing key once per branch in the volume/filer JWT auth checks, so a reload landing mid-check can't take the allow-fast-path after auth was enabled or verify against a different key than the branch saw.
320 lines
9.7 KiB
Go
320 lines
9.7 KiB
Go
package weed_server
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"net/http"
|
|
"path"
|
|
"strconv"
|
|
"strings"
|
|
"sync/atomic"
|
|
"time"
|
|
|
|
"github.com/seaweedfs/seaweedfs/weed/filer"
|
|
"github.com/seaweedfs/seaweedfs/weed/glog"
|
|
"github.com/seaweedfs/seaweedfs/weed/pb/filer_pb"
|
|
"github.com/seaweedfs/seaweedfs/weed/security"
|
|
"github.com/seaweedfs/seaweedfs/weed/stats"
|
|
"github.com/seaweedfs/seaweedfs/weed/util/version"
|
|
)
|
|
|
|
func (fs *FilerServer) filerHandler(w http.ResponseWriter, r *http.Request) {
|
|
start := time.Now()
|
|
|
|
inFlightGauge := stats.FilerInFlightRequestsGauge.WithLabelValues(r.Method)
|
|
inFlightGauge.Inc()
|
|
defer inFlightGauge.Dec()
|
|
|
|
statusRecorder := stats.NewStatusResponseWriter(w)
|
|
w = statusRecorder
|
|
origin := r.Header.Get("Origin")
|
|
if origin != "" {
|
|
if fs.option.AllowedOrigins == nil || len(fs.option.AllowedOrigins) == 0 || fs.option.AllowedOrigins[0] == "*" {
|
|
origin = "*"
|
|
} else {
|
|
originFound := false
|
|
for _, allowedOrigin := range fs.option.AllowedOrigins {
|
|
if origin == allowedOrigin {
|
|
originFound = true
|
|
}
|
|
}
|
|
if !originFound {
|
|
writeJsonError(w, r, http.StatusForbidden, errors.New("origin not allowed"))
|
|
return
|
|
}
|
|
}
|
|
|
|
w.Header().Set("Access-Control-Allow-Origin", origin)
|
|
w.Header().Set("Access-Control-Expose-Headers", "*")
|
|
w.Header().Set("Access-Control-Allow-Headers", "*")
|
|
w.Header().Set("Access-Control-Allow-Credentials", "true")
|
|
w.Header().Set("Access-Control-Allow-Methods", "PUT, POST, GET, DELETE, OPTIONS")
|
|
}
|
|
|
|
if r.Method == http.MethodOptions {
|
|
OptionsHandler(w, r, false)
|
|
return
|
|
}
|
|
|
|
// proxy to volume servers
|
|
var fileId string
|
|
if strings.HasPrefix(r.RequestURI, "/?proxyChunkId=") {
|
|
fileId = r.RequestURI[len("/?proxyChunkId="):]
|
|
}
|
|
if fileId != "" {
|
|
fs.proxyToVolumeServer(w, r, fileId)
|
|
stats.FilerHandlerCounter.WithLabelValues(stats.ChunkProxy).Inc()
|
|
stats.FilerRequestHistogram.WithLabelValues(stats.ChunkProxy).Observe(time.Since(start).Seconds())
|
|
return
|
|
}
|
|
requestMethod := r.Method
|
|
defer func(method *string) {
|
|
stats.FilerRequestCounter.WithLabelValues(*method, strconv.Itoa(statusRecorder.Status)).Inc()
|
|
stats.FilerRequestHistogram.WithLabelValues(*method).Observe(time.Since(start).Seconds())
|
|
}(&requestMethod)
|
|
|
|
isReadHttpCall := r.Method == http.MethodGet || r.Method == http.MethodHead
|
|
if !fs.maybeCheckJwtAuthorization(r, !isReadHttpCall) {
|
|
writeJsonError(w, r, http.StatusUnauthorized, errors.New("wrong jwt"))
|
|
return
|
|
}
|
|
|
|
w.Header().Set("Server", "SeaweedFS "+version.VERSION)
|
|
|
|
switch r.Method {
|
|
case http.MethodGet, http.MethodHead:
|
|
fs.GetOrHeadHandler(w, r)
|
|
case http.MethodDelete:
|
|
if _, ok := r.URL.Query()["tagging"]; ok {
|
|
fs.DeleteTaggingHandler(w, r)
|
|
} else {
|
|
fs.DeleteHandler(w, r)
|
|
}
|
|
case http.MethodPost, http.MethodPut:
|
|
// wait until in flight data is less than the limit
|
|
contentLength := getContentLength(r)
|
|
fs.inFlightDataLimitCond.L.Lock()
|
|
inFlightDataSize := atomic.LoadInt64(&fs.inFlightDataSize)
|
|
inFlightUploads := atomic.LoadInt64(&fs.inFlightUploads)
|
|
|
|
// Wait if either data size limit or file count limit is exceeded
|
|
for (fs.option.ConcurrentUploadLimit != 0 && inFlightDataSize > fs.option.ConcurrentUploadLimit) || (fs.option.ConcurrentFileUploadLimit != 0 && inFlightUploads >= fs.option.ConcurrentFileUploadLimit) {
|
|
if fs.option.ConcurrentUploadLimit != 0 && inFlightDataSize > fs.option.ConcurrentUploadLimit {
|
|
glog.V(4).Infof("wait because inflight data %d > %d", inFlightDataSize, fs.option.ConcurrentUploadLimit)
|
|
}
|
|
if fs.option.ConcurrentFileUploadLimit != 0 && inFlightUploads >= fs.option.ConcurrentFileUploadLimit {
|
|
glog.V(4).Infof("wait because inflight uploads %d >= %d", inFlightUploads, fs.option.ConcurrentFileUploadLimit)
|
|
}
|
|
fs.inFlightDataLimitCond.Wait()
|
|
inFlightDataSize = atomic.LoadInt64(&fs.inFlightDataSize)
|
|
inFlightUploads = atomic.LoadInt64(&fs.inFlightUploads)
|
|
}
|
|
fs.inFlightDataLimitCond.L.Unlock()
|
|
|
|
// Increment counters
|
|
newUploads := atomic.AddInt64(&fs.inFlightUploads, 1)
|
|
newSize := atomic.AddInt64(&fs.inFlightDataSize, contentLength)
|
|
// Update metrics
|
|
stats.FilerInFlightUploadCountGauge.Set(float64(newUploads))
|
|
stats.FilerInFlightUploadBytesGauge.Set(float64(newSize))
|
|
defer func() {
|
|
// Decrement counters
|
|
newUploads := atomic.AddInt64(&fs.inFlightUploads, -1)
|
|
newSize := atomic.AddInt64(&fs.inFlightDataSize, -contentLength)
|
|
// Update metrics
|
|
stats.FilerInFlightUploadCountGauge.Set(float64(newUploads))
|
|
stats.FilerInFlightUploadBytesGauge.Set(float64(newSize))
|
|
fs.inFlightDataLimitCond.Signal()
|
|
}()
|
|
|
|
if r.Method == http.MethodPut {
|
|
if _, ok := r.URL.Query()["tagging"]; ok {
|
|
fs.PutTaggingHandler(w, r)
|
|
} else {
|
|
fs.PostHandler(w, r, contentLength)
|
|
}
|
|
} else { // method == "POST"
|
|
fs.PostHandler(w, r, contentLength)
|
|
}
|
|
default:
|
|
requestMethod = "INVALID"
|
|
w.WriteHeader(http.StatusMethodNotAllowed)
|
|
}
|
|
}
|
|
|
|
func (fs *FilerServer) readonlyFilerHandler(w http.ResponseWriter, r *http.Request) {
|
|
|
|
start := time.Now()
|
|
statusRecorder := stats.NewStatusResponseWriter(w)
|
|
w = statusRecorder
|
|
|
|
glog.V(4).Infof("Request: %s %s", r.Method, r.URL.Path)
|
|
|
|
origin := r.Header.Get("Origin")
|
|
if origin != "" {
|
|
if fs.option.AllowedOrigins == nil || len(fs.option.AllowedOrigins) == 0 || fs.option.AllowedOrigins[0] == "*" {
|
|
origin = "*"
|
|
} else {
|
|
originFound := false
|
|
for _, allowedOrigin := range fs.option.AllowedOrigins {
|
|
if origin == allowedOrigin {
|
|
originFound = true
|
|
}
|
|
}
|
|
if !originFound {
|
|
writeJsonError(w, r, http.StatusForbidden, errors.New("origin not allowed"))
|
|
return
|
|
}
|
|
}
|
|
|
|
w.Header().Set("Access-Control-Allow-Origin", origin)
|
|
w.Header().Set("Access-Control-Allow-Headers", "OPTIONS, GET, HEAD")
|
|
w.Header().Set("Access-Control-Allow-Credentials", "true")
|
|
}
|
|
requestMethod := r.Method
|
|
defer func(method *string) {
|
|
stats.FilerRequestCounter.WithLabelValues(*method, strconv.Itoa(statusRecorder.Status)).Inc()
|
|
stats.FilerRequestHistogram.WithLabelValues(*method).Observe(time.Since(start).Seconds())
|
|
}(&requestMethod)
|
|
// We handle OPTIONS first because it never should be authenticated
|
|
if r.Method == http.MethodOptions {
|
|
OptionsHandler(w, r, true)
|
|
return
|
|
}
|
|
|
|
if !fs.maybeCheckJwtAuthorization(r, false) {
|
|
writeJsonError(w, r, http.StatusUnauthorized, errors.New("wrong jwt"))
|
|
return
|
|
}
|
|
|
|
w.Header().Set("Server", "SeaweedFS "+version.VERSION)
|
|
|
|
switch r.Method {
|
|
case http.MethodGet, http.MethodHead:
|
|
fs.GetOrHeadHandler(w, r)
|
|
default:
|
|
requestMethod = "INVALID"
|
|
w.WriteHeader(http.StatusMethodNotAllowed)
|
|
}
|
|
}
|
|
|
|
func OptionsHandler(w http.ResponseWriter, r *http.Request, isReadOnly bool) {
|
|
if isReadOnly {
|
|
w.Header().Set("Access-Control-Allow-Methods", "GET, OPTIONS")
|
|
} else {
|
|
w.Header().Set("Access-Control-Allow-Methods", "PUT, POST, GET, DELETE, OPTIONS")
|
|
w.Header().Set("Access-Control-Expose-Headers", "*")
|
|
}
|
|
w.Header().Set("Access-Control-Allow-Headers", "*")
|
|
w.Header().Set("Access-Control-Allow-Credentials", "true")
|
|
}
|
|
|
|
// maybeCheckJwtAuthorization returns true if access should be granted, false if it should be denied
|
|
func (fs *FilerServer) maybeCheckJwtAuthorization(r *http.Request, isWrite bool) bool {
|
|
|
|
if !isWrite && r.URL.Path == "/" {
|
|
return true
|
|
}
|
|
|
|
var signingKey security.SigningKey
|
|
|
|
if isWrite {
|
|
signingKey = fs.filerGuard.SigningKey()
|
|
if len(signingKey) == 0 {
|
|
return true
|
|
}
|
|
} else {
|
|
signingKey = fs.filerGuard.ReadSigningKey()
|
|
if len(signingKey) == 0 {
|
|
return true
|
|
}
|
|
}
|
|
|
|
tokenStr := security.GetJwt(r)
|
|
if tokenStr == "" {
|
|
glog.V(1).Infof("missing jwt from %s", r.RemoteAddr)
|
|
return false
|
|
}
|
|
|
|
token, err := security.DecodeJwt(signingKey, tokenStr, &security.SeaweedFilerClaims{})
|
|
if err != nil {
|
|
glog.V(1).Infof("jwt verification error from %s: %v", r.RemoteAddr, err)
|
|
return false
|
|
}
|
|
if !token.Valid {
|
|
glog.V(1).Infof("jwt invalid from %s: %v", r.RemoteAddr, tokenStr)
|
|
return false
|
|
}
|
|
|
|
claims, ok := token.Claims.(*security.SeaweedFilerClaims)
|
|
if !ok {
|
|
glog.V(1).Infof("jwt claims not of type *SeaweedFilerClaims from %s", r.RemoteAddr)
|
|
return false
|
|
}
|
|
|
|
if len(claims.AllowedPrefixes) > 0 {
|
|
hasPrefix := false
|
|
for _, prefix := range claims.AllowedPrefixes {
|
|
if pathHasComponentPrefix(r.URL.Path, prefix) {
|
|
hasPrefix = true
|
|
break
|
|
}
|
|
}
|
|
if !hasPrefix {
|
|
glog.V(1).Infof("jwt path not allowed from %s: %v", r.RemoteAddr, r.URL.Path)
|
|
return false
|
|
}
|
|
}
|
|
if len(claims.AllowedMethods) > 0 {
|
|
hasMethod := false
|
|
for _, method := range claims.AllowedMethods {
|
|
if method == r.Method {
|
|
hasMethod = true
|
|
break
|
|
}
|
|
}
|
|
if !hasMethod {
|
|
glog.V(1).Infof("jwt method not allowed from %s: %v", r.RemoteAddr, r.Method)
|
|
return false
|
|
}
|
|
}
|
|
|
|
return true
|
|
}
|
|
|
|
// pathHasComponentPrefix reports whether reqPath is contained within the
|
|
// directory subtree denoted by prefix, treating both as "/"-separated
|
|
// path components. Both inputs are normalised with path.Clean to neutralise
|
|
// "." and ".." segments and collapse duplicate slashes. A prefix of "/"
|
|
// matches any path.
|
|
func pathHasComponentPrefix(reqPath, prefix string) bool {
|
|
if prefix == "" {
|
|
return false
|
|
}
|
|
cleanedPath := path.Clean(reqPath)
|
|
if cleanedPath == "." {
|
|
cleanedPath = "/"
|
|
}
|
|
cleanedPrefix := path.Clean(prefix)
|
|
if cleanedPrefix == "." {
|
|
cleanedPrefix = "/"
|
|
}
|
|
if cleanedPrefix == "/" {
|
|
return true
|
|
}
|
|
if cleanedPath == cleanedPrefix {
|
|
return true
|
|
}
|
|
return strings.HasPrefix(cleanedPath, cleanedPrefix+"/")
|
|
}
|
|
|
|
func (fs *FilerServer) filerHealthzHandler(w http.ResponseWriter, r *http.Request) {
|
|
w.Header().Set("Server", "SeaweedFS "+version.VERSION)
|
|
if _, err := fs.filer.Store.FindEntry(context.Background(), filer.TopicsDir); err != nil && err != filer_pb.ErrNotFound {
|
|
glog.Warningf("filerHealthzHandler FindEntry: %+v", err)
|
|
w.WriteHeader(http.StatusServiceUnavailable)
|
|
} else {
|
|
w.WriteHeader(http.StatusOK)
|
|
}
|
|
}
|